CVE-2013-0856
published 2013-12-07CVE-2013-0856: The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio…
PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.11%
79.9th percentile
The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_samples value.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 1.0 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-0856: ffmpeg - The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows rem...
vendor_debian·2013·CVSS 9.3
CVE-2013-0856 [CRITICAL] CVE-2013-0856: ffmpeg - The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows rem...
The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_samples value.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-75w2-3wg9-gp9c: The lpc_prediction function in libavcodec/alac
ghsa_unreviewed·2022-05-17
CVE-2013-0856 [HIGH] CWE-20 GHSA-75w2-3wg9-gp9c: The lpc_prediction function in libavcodec/alac
The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_samples value.
OSV
CVE-2013-0856: The lpc_prediction function in libavcodec/alac
osv·2013-12-07·CVSS 9.3
CVE-2013-0856 [CRITICAL] CVE-2013-0856: The lpc_prediction function in libavcodec/alac
The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_samples value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1886 Certificate System: pki-tps format string injection
bugzilla·2013-03-22·CVSS 7.5
CVE-2013-1886 [HIGH] CVE-2013-1886 Certificate System: pki-tps format string injection
CVE-2013-1886 Certificate System: pki-tps format string injection
It was reported that Certificate System suffers from a format string injection flaw when viewing certificates. This could allow a remote attacker to crash the Certificate System server or, possibly, execute arbitrary code with the privileges of the user runnin the service (typically run as an unprivileged user, such as pkiuser).
This was reported against Certificate System 8.1 and may also affect Dogtag 9 and 10.
Discussion:
Created pki-tps tracking bugs for this issue
Affects: fedora-all [bug 966189]
Affects: epel-5 [bug 966190]
---
This issue has been addressed in following products:
Red Hat Certificate System 8
Via RHSA-2013:0856 https://rhn.redhat.com/errata/RHSA-2013-0856.html
---
pki-tps-9.0.11-1.fc17 has be
Bugzilla
CVE-2013-1885 Certificate System: pki-tps XSS flaw
bugzilla·2013-03-19·CVSS 4.3
CVE-2013-1885 [MEDIUM] CVE-2013-1885 Certificate System: pki-tps XSS flaw
CVE-2013-1885 Certificate System: pki-tps XSS flaw
It was reported that Certificate System suffers from XSS flaws in the /tus/ and /tus/tus/ URLs, such as:
GET /tus/tus/%22%2b%61%6c%65%72%74%28%34%38%32%36%37%29%2b%22
or
GET /tus/%22%2b%61%6c%65%72%74%28%36%31%34%35%32%29%2b%22
which will in turn output something like:
<!--
var uriBase = "/tus/"+alert(85384)+";
var userid = "admin";
This was reported against Certificate System 8.1 and may also affect Dogtag 9 and 10.
Discussion:
Created pki-tps tracking bugs for this issue
Affects: fedora-all [bug 966189]
Affects: epel-5 [bug 966190]
---
This issue has been addressed in following products:
Red Hat Certificate System 8
Via RHSA-2013:0856 https://rhn.redhat.com/errata/RHSA-2013-0856.html
---
pki-tps-9.0.11-1.fc17 has been p
2013-12-07
Published